🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 89b5e9e35e796a62e0ffc96fd8f2ee6715d8837ea13db6b2be222be6bc87cdfc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gozi


Vendor detections: 8


Intelligence 8 IOCs YARA 1 File information Comments

SHA256 hash: 89b5e9e35e796a62e0ffc96fd8f2ee6715d8837ea13db6b2be222be6bc87cdfc
SHA3-384 hash: 971f3d12ce8f80074a96e2b6b42fac4cd507c0a42d16ce4a444f12599222051ea03b325e96befa8db0484dbe51305b8f
SHA1 hash: d8c1102b6bf8f3f5659df3550f1063643ed66f50
MD5 hash: 593d69ac0e94b82c2522a7e6d7b2c55a
humanhash: bluebird-bravo-oscar-hawaii
File name:Agenzia_E3.hta
Download: download sample
Signature Gozi
File size:7'162 bytes
First seen:2023-02-09 19:12:33 UTC
Last seen:Never
File type:HTML Application (hta) hta
MIME type:application/octet-stream
ssdeep 96:SP1jWsLmNEbJPl0EJjAr3BZE5S4dwatCu2WJ3f2Wgw9RKUzVj5q4NaM+12AVool7:S3DFF6r/TC0u2W37V5q0aM0wqr
TLSH T1D3E16DCFAECB601B571762E66D723E0CBE222630D8908024BFF4E75EA765B1351416AD
TrID 80.6% (.HTM/HTML) HyperText Markup Language with DOCTYPE (12501/2/4)
19.3% (.HTML) HyperText Markup Language (3000/1/1)
Reporter JAMESWT_WT
Tags:agenziaentrate Gozi

Intelligence


File Origin
# of uploads :
1
# of downloads :
78
Origin country :
IT IT
Vendor Threat Intelligence
Verdict:
Malicious
Labled as:
Trojan.Cryxos.11751;JS:Trojan.Cryxos.JS
Result
Threat name:
Unknown
Detection:
malicious
Classification:
evad
Score:
52 / 100
Signature
Antivirus detection for URL or domain
Tries to download files via bitsadmin
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 803749 Sample: Agenzia_E3.hta Startdate: 10/02/2023 Architecture: WINDOWS Score: 52 14 Antivirus detection for URL or domain 2->14 7 mshta.exe 13 2->7         started        process3 signatures4 16 Tries to download files via bitsadmin 7->16 10 bitsadmin.exe 1 7->10         started        process5 process6 12 conhost.exe 10->12         started       
Threat name:
Document-HTML.Trojan.Ursnif
Status:
Malicious
First seen:
2023-02-09 19:04:22 UTC
File Type:
Text (HTML)
Extracted files:
2
AV detection:
9 of 26 (34.62%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:QbotStuff
Author:anonymous

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments